< ciso
brief />
Tag Banner

All news with #microsoft tag

1054 articles · page 2 of 53

Windows 11 2026 Update rollout and key details

🛈 Microsoft has begun broad rollout of the Windows 11 2026 Update (26H2), but most users will see incremental changes since many features were already delivered via monthly updates. The update installs as a small enablement package for systems on 24H2 or 25H2, making it more like a regular cumulative update. Devices that shipped with 26H1 cannot upgrade directly to 26H2, and installing 26H2 resets the support lifecycle (24 months for Home/Pro, 36 months for Enterprise/Education).
read more →

SQL Server on Azure Local Now Generally Available

🔔 Today Microsoft announced that SQL Server on Azure Local is generally available for both connected and disconnected operations, enabling organizations to run SQL Server on Azure-consistent infrastructure in customer datacenters and edge locations. The offering supports modernized deployments while preserving local control, data sovereignty, and licensing options. Customers can also preview Foundry Local to run AI inference alongside SQL Server on Azure Local.
read more →

Compromised Identity Leads to Broad DevOps and Cloud Access

🔒 Microsoft DART investigated an incident where the Storm-3068 actor turned a self-service password reset into persistent access across Azure DevOps, development pipelines, and Kubernetes. The actor used legitimate identity and cloud services to enumerate repositories, create malicious pipelines to harvest kubeconfig files, and deploy remote access tools like Atera and Chisel. DART worked with the customer to contain the intrusion, reconstruct activity from audit logs and Git history, and provide remediation guidance to reduce future identity-driven risks.
read more →

Microsoft advances Fabric, Copilot, and data apps

🔔 Microsoft showcased Fabric and SQL innovations at FabCon and SQLCon 2026 in Barcelona, highlighting integrations across Microsoft Copilot, Fabric IQ, Power BI agentic apps, and OneLake. The announcements include Fabric IQ in Copilot, agentic app creation in Power BI Desktop, Fabric Apps enhancements for developers, and IQ sharing for governed data collaboration. These updates aim to ground AI in trusted business context and speed production-ready app development.
read more →

NeedyMantis malware enables persistent access

🔒 Microsoft analyzed a malware family called NeedyMantis, used to maintain long-term access in targeted intrusions affecting telecoms, universities, medical nonprofits, intergovernmental organizations, and contractors. The activity dates back to at least October 2025 and was discovered while investigating the DAEMON Tools supply chain compromise. NeedyMantis operates via DLL sideloading: a legitimate program, a malicious DLL, and an encrypted archive load in sequence to unpack and run a main component that connects to a C2 over HTTPS and WebSocket. Microsoft published file hashes, domains, file paths, hunting queries, and Defender detection names to help defenders identify and remediate infections.
read more →

NeedyMantis: Modular post‑compromise malware analysis

🛡️ Microsoft Threat Intelligence describes NeedyMantis, a modular post‑compromise malware family observed since October 2025 in targeted intrusions against telecoms, universities, medical nonprofits, intergovernmental organizations, and government contractors. The malware is typically deployed after initial access to maintain persistent access and support follow‑on operations. NeedyMantis uses multiple loaders, a custom encrypted archive format, a bespoke executable layout, and modular components to evade analysis and extend capability. Microsoft links observed activity to Storm‑3069 and activity consistent with Chinese‑aligned threat actors, and provides IOCs, Defender detections, and mitigations.
read more →

Microsoft pauses KB5002907 after Office license issues

🛑 Microsoft has paused rollout of the KB5002907 Microsoft 365 update after reports it deactivated or removed perpetual Office 2016 and 2019 installs. The optional update, intended for Microsoft 365 Apps >90 days out of date, reportedly installed on some perpetual installs and caused 'Unlicensed Product' states or full removal. Microsoft confirmed the pause and is investigating, advising reactivation or reinstallation where necessary. The company updated the support bulletin and will provide further guidance.
read more →

CISA Adds SharePoint and MikroTik Flaws to KEV List

🔐 CISA has added two actively exploited vulnerabilities—CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS—to its Known Exploited Vulnerabilities catalog. Microsoft updated its advisory to reflect that the SharePoint issue can be leveraged for remote code execution, while CERT Polska and researchers linked RouterOS flaws to a full administrative takeover exploit called MikroTrick. Federal agencies must patch these issues by September 28, 2026.
read more →

CISA Alerts: Active Exploits in WSO2, Adobe, SharePoint

⚠️ CISA warns that multiple critical and high-severity vulnerabilities in WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS are being actively exploited. Two critical flaws—CVE-2026-5430 in WSO2 and CVE-2026-71362 in Adobe Commerce—were added to the Known Exploited Vulnerabilities catalog with federal mitigation deadlines. Agencies must patch or mitigate by the specified dates, and organizations are urged to prioritize these fixes.
read more →

Microsoft to deprecate Windows Deployment Services

🖥️ Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. WDS, a successor to RIS, enabled network-based OS installs at scale but has seen partial deprecation steps since 2021, including removed features and reduced support for desktop OS deployment. Microsoft recommends migrating to alternatives such as Configuration Manager and notes current supported Server releases remain unaffected until removal.
read more →

Microsoft Foundry enhances agent model choice and tooling

🛠️ Microsoft announces updates to Foundry, offering expanded model options, native voice agents, long-running resilience, and continuous optimization tools to help teams build and operate production agents faster. The platform now supports recent frontier models like GPT-6 family and Claude Opus 5.5, voice agents in public preview with expressive multi-lingual capabilities, and developer tooling such as the Foundry Toolkit for VS Code. Enterprise governance features integrate with Microsoft Entra and include network egress controls, audit capabilities, and upcoming AI Gateway integration for centralized policy management.
read more →

September 2026 Microsoft Security updates and features

🔒 This post summarizes September 2026 security updates across Microsoft Security, highlighting new controls for local AI agents, expanded Zero Trust for agentic traffic, and SOC improvements. It covers AI-powered detonation summaries for emails, Purview and Entra integration for data protection, Purview auto-labeling and eDiscovery enhancements, data lifecycle management for SharePoint, and new GCC High capabilities for Intune and PKI.
read more →

Microsoft adds integrated SOC features to Defender

🔒 Microsoft now offers Integrated Security Operations Center (ISOC) capabilities inside Microsoft Defender for Microsoft 365 E5 and E7 customers at no extra license cost during public preview. ISOC combines SIEM-like functions with Defender XDR, threat intelligence, automation and AI in a single portal, and ingests Microsoft product logs without charges. From Oct. 1, third-party data ingestion will be metered at $2.40 per GB, and more advanced features require an ISOC workspace and Azure subscription.
read more →

Windows 11 preview KB5124010 adds 46 fixes

🛠️ Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, delivering 46 changes including Bluetooth fixes and the ability to remap the Copilot key. This optional update focuses on quality improvements and new features—such as Emoji 17.0 support, an Open apps maximized accessibility option, and a WinRE remote management plug-in—without including security patches. Administrators can install it via Settings > Windows Update or manually from the Microsoft Update Catalog, and it upgrades affected systems to builds 26200.9550 and 26100.9550.
read more →

Most Organizations Face Microsoft 365 Governance Incidents

📊 ShareGate's State of Microsoft 365 report found 77% of global organizations experienced at least one Microsoft 365 governance incident in the past year. The survey of nearly 1,800 IT professionals across nine countries highlights failures such as lingering access for former users, audit and compliance gaps, and sensitive data reaching unintended recipients. Rapid AI adoption and overconfidence in AI controls, plus limited proactive monitoring, are cited as key drivers of increased risk.
read more →

Microsoft fixes File History backup issue in September patch

🛠️ Microsoft addressed a known issue that caused the built-in File History backup to fail after installing September 2026 security updates. Affected systems experienced FileHistory.exe crashes, "Reconnect your drive" alerts despite attached drives, and missing previous file versions. The vendor says the fix is included in the September preview update for Windows 11, with broader availability on Patch Tuesday (October 13) for users who defer optional updates. Microsoft previously also issued out-of-band fixes for other September update regressions.
read more →

Reimagining the SOC for the agentic era

🔐 Microsoft announces an Integrated Security Operations Center (ISOC) in Microsoft Defender to unify SIEM and threat protection into a single platform. ISOC provides combined signals, context, and actuators so humans and agents can operate as one system, enabling faster detection, investigation, and automated response. The preview is available now.
read more →

September 2026 Windows update disrupts Always On VPN

🔒 Microsoft warned administrators that the September 2026 Windows 11 security updates can cause Always On VPN connections to stall or repeatedly fail. The issue appears when profiles use automatic protocol selection between IKEv2 and SSTP, leaving connections stuck in a "Connecting" state or returning "The specified port is already in use." A temporary mitigation is to set the VPN profile to use either SSTP-only or IKEv2-only while Microsoft develops a permanent fix.
read more →

Microsoft disruption exposes AI-driven phishing-as-a-service

🔎 Microsoft says it disrupted EvilTokens, an AI-powered phishing-as-a-service platform that compromised over 12,000 Microsoft 365 inboxes across more than 10,000 organizations. Launched in February 2026, EvilTokens combined account compromise, mailbox analysis, target selection, and fraud preparation behind a subscription dashboard and chatbot. The operation abused Microsoft’s OAuth 2.0 device-code flow to steal session tokens and used an AI analyst to scan mailboxes and craft business email compromise scams. Microsoft seized infrastructure via a US court order and partners arrested two suspects in the UK amid coordinated takedown efforts.
read more →

Claude Opus 5.5 in Microsoft Foundry for Long Tasks

🧭 Claude Opus 5.5 is now available in Microsoft Foundry, bringing Anthropic’s Opus advances to developers and enterprises for long-running coding and knowledge work. The model emphasizes sustained focus, adaptive reasoning, and clearer agentic communication while lowering token costs and enabling cache efficiencies. It also introduces expanded safeguards and new beta API capabilities tailored for long-lived agent architectures.
read more →